The ACH Network moved 35.2 billion payments worth $93 trillion in 2025, according to Nacha — volume up nearly 5% and value up almost 8% over 2024. For most of that network's history, the rulebook asked comparatively little of the parties originating those payments when it came to detecting fraud. That changed during 2026.
Nacha's Risk Management rule package phased in new fraud monitoring obligations in two stages. The first took effect March 20, 2026 and captured the largest originators. The second took effect June 19, 2026 and removed the volume threshold entirely. Both are now in force. If your organization originates ACH entries, or performs any part of ACH processing on someone else's behalf — which describes a great many ISOs and payment facilitators — you are very likely in scope, whatever your volume.
A good deal of the guidance published about these rules was written while they were still forthcoming and reads in the future tense. Here is what they require now, drawn from Nacha's own rule pages and FAQs.
What changed, and when
Before these amendments, Nacha's rules required Originators to use a commercially reasonable fraudulent transaction detection system for two things only: WEB debits and Micro-Entries. Nacha's own description of the gap is blunt — those requirements "did not encompass any other transaction types, and so did not apply to other types of debits or to any credits other than Micro-Entries."
The amendments widen that considerably, along two parallel tracks.
Fraud monitoring on the origination side
- Phase 1, effective March 20, 2026: all ODFIs, plus every non-consumer Originator, Third-Party Service Provider and Third-Party Sender whose 2023 ACH origination volume was 6 million entries or greater.
- Phase 2, effective June 19, 2026: every remaining non-consumer Originator, Third-Party Service Provider and Third-Party Sender, regardless of volume.
Credit monitoring on the receiving side
- Phase 1, effective March 20, 2026: RDFIs with 2023 ACH receipt volume of 10 million or greater.
- Phase 2, effective June 19, 2026: all other RDFIs.
One scheduling note worth keeping in your records: Nacha points out that June 19 is a federal holiday, so the practical effective date for the Phase 2 rules was the next banking day, Monday, June 22, 2026.
Why Third-Party Senders should read this twice
The scoping language is broad. Nacha's FAQ states that the requirements apply to "each ODFI, each non-consumer Originator, each Third-Party Sender, and each Third-Party Service Provider that performs any functions of ACH processing on behalf of an Originator, Third-Party Sender, or ODFI."
That last clause is the one that catches merchant-services businesses. If you perform any part of ACH processing for someone else, the obligation attaches to you directly — not merely to the bank whose program you sit under. And after Phase 2 there is no volume floor left to fall below.
The rules do temper this. The obligation applies, in Nacha's phrasing, "to the extent relevant to the role the entity plays." A Third-Party Sender is not expected to run the controls an ODFI runs. It is expected to run controls appropriate to what it actually does.
What the rule requires — and what it doesn't
Stripped to essentials, covered parties must do two things:
- Establish and implement risk-based processes and procedures, relevant to the role the party plays in the authorization or transmission of entries, reasonably intended to identify entries suspected of being unauthorized or authorized under False Pretenses.
- Review those processes and procedures at least annually, and make appropriate updates to address evolving risks.
Equally important is what Nacha declined to require. Its FAQ answers three questions with a flat no:
- The rules do not prescribe specific processes, procedures or technologies.
- They do not require screening every ACH entry individually.
- They do not require monitoring before entries are processed. Nacha notes that pre-processing monitoring "provides the greatest opportunity for detecting and preventing potential fraud" — it is simply not mandatory.
The drafting changes Nacha made between the original 2023 request for comment and the final rule point the same direction. The standard of "commercially reasonable" was eliminated, and "detection system" was replaced with "processes and procedures." The obligation is to run a defensible process, not to buy a particular product.
One caution, though: risk-based does not mean optional. Nacha states that a risk-based approach "should not be used, however, to conclude that no monitoring is necessary at all," and that at minimum an entity should conduct a risk assessment identifying and differentiating higher-risk from lower-risk transactions.
"False Pretenses" is a new defined term
The amendments introduce a defined term, False Pretenses: the inducement of a payment by a person misrepresenting their identity, their association with or authority to act on behalf of another person, or the ownership of an account to be credited.
Per Nacha, that covers business email compromise, vendor impersonation, payroll impersonation and other payee impersonations, and complements the existing language on unauthorized credits, which addresses account takeover.
It does not cover scams involving fake, non-existent or poor-quality goods or services. That boundary matters when you scope what your monitoring is meant to catch: a dispute about goods that never arrived is not what this rule is aimed at.
The two new Company Entry Descriptions
Effective March 20, 2026 — one date for all Originators, not split into phases like the fraud monitoring rules — Originators must use two standardized values in the Company Entry Description field, which sits at positions 54–63 of the Company/Batch Header Record and holds a maximum of ten characters:
- PAYROLL, for PPD credits paying wages, salaries and similar compensation. Nacha's stated aims are reducing payroll redirection fraud and helping RDFIs apply funds-availability logic.
- PURCHASE, for consumer e-commerce purchases — defined as a debit entry authorized by a consumer Receiver for the online purchase of goods, including recurring purchases first authorized online, using the WEB debit SEC code, or TEL where the standing authorization rule permits it.
Note the limit of the PURCHASE requirement. The rule expressly says the ODFI "has no obligation to verify the presence or accuracy of the word 'PURCHASE' as a description of purpose." The obligation sits with the Originator, and nobody downstream is policing it for you.
What monitoring can look like in practice
Because the rules are neutral on method, Nacha's Credit-Push Fraud Monitoring Resource Center offers possibilities rather than requirements: velocity checks, anomaly detection, behavioral tolerances and pattern recognition.
The FAQs get more concrete about who is best placed to watch what:
- Originators may be best placed to guard against account takeover and similar vectors — for instance, change controls over payment information and instructions for vendor and payroll payments.
- Third-Party Senders and Third-Party Service Providers involved in origination may review the volume, velocity, dollar amounts and SEC codes of the entries they originate.
The rules also let an ODFI's processes take account of what other parties in the origination chain are doing. Nacha's condition is that the basis for that reliance "should be reasonable and clear (e.g., allocated by contract and verified by appropriate oversight)." And the flexibility runs one way only: controls implemented by RDFIs and other receiving-side participants "do not affect the obligations of originating participants."
When monitoring flags something, Nacha lists actions an ODFI can consider — stopping further processing of the flagged transaction, consulting the Originator on its validity, checking whether other internal monitoring systems have flagged it, and contacting the RDFI, either to learn whether the Receiver's account raises further red flags or to request a freeze or the return of funds.
The annual review is the part that will bite
The obligation that is easiest to satisfy once and hardest to sustain is the annual review. It is written into the rule itself, not offered as best practice.
Writing for Nacha in April 2026, after Phase 1 had landed, senior consultant Mark Dixon made the point directly: the rules are "not intended to be a one-time compliance exercise," and "the requirement to review these processes at least annually is baked into the Rule requirements." Risk profiles shift with new products, evolving fraud schemes, customer behavior, technology changes and operational growth.
For a merchant-services business, the practical implication is ownership. Someone has to hold the document, run the review on a date that exists in a real calendar, and record what changed. A monitoring tool with nobody accountable for reassessing it is not what the rule asks for.
If you are behind
A reasonable order of work, given how the rules are written:
- Establish which role or roles you occupy — non-consumer Originator, Third-Party Sender, Third-Party Service Provider. Obligations attach to the role, and some businesses occupy more than one.
- Conduct and document a risk assessment that separates higher-risk from lower-risk activity. Nacha treats this as the floor beneath any risk-based approach.
- Write down the processes and procedures you actually run, mapped to your role. The rule asks for processes and procedures, and undocumented practice is difficult to evidence.
- Fix the review date and the owner now, so the first annual cycle is not discovered late.
Nacha publishes the rule pages, the FAQs and its Risk Management Advisory Group guidance openly, and the Credit-Push Fraud Monitoring Resource Center lists third-party vendors offering monitoring services — with an explicit note that the list is neither inclusive nor an endorsement. For anything that turns on exact wording, the Nacha Operating Rules remain the authority.
Tags
About the author

Kyle Hall
Founder
Kyle Hall is a fintech entrepreneur, software engineer, and marketing strategist with over a decade of experience in high-risk payment processing and SaaS development. He is the CEO of PayKings, a leader in high-risk merchant services, and the founder of PulseCRM, a purpose-built CRM platform for the payments industry. Kyle specializes in building custom payment processing systems and growth strategies that empower merchant services providers to scale and succeed in the digital marketplace.
